Updated openjpeg2 packages fix security vulnerability
Publication date: 02 Mar 2021Type: security
Affected Mageia releases : 7
CVE: CVE-2020-27844
Description
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. (CVE-2020-27844).
References
SRPMS
7/core
- openjpeg2-2.4.0-1.mga7